Skip to main content
Guide

Claude watermark remover: what actually removes SynthID

Anthropic began watermarking Claude on 2 August 2026. The mark is not a hidden character and you cannot strip it out. Here is what it is, what the removal tools are really doing, and the one thing Anthropic says gets rid of it.

Last updated August 21, 2026 · 10 min read

0 / 300 words

A full rewrite replaces the word choices the watermark lives in. We cannot show you a before-and-after watermark score, because Anthropic has not released the detector that would produce one.

2 Aug 2026
Watermarking began
SynthID
Method Anthropic uses
0
Hidden characters added
Not yet
Public detector released

Key takeaways

  • Anthropic's own documentation says it plainly: "Nothing is added to the text and there are no hidden characters." The watermark is a pattern in which words Claude picked.
  • Every tool selling "Claude watermark removal" by stripping zero-width characters is removing something that was never in the text.
  • Anthropic's own words on what does work: light editing probably will not remove the watermark completely, but a complete rewrite where every word is replaced will.
  • Nobody can currently verify removal on Claude output. The detection API is announced but unreleased, so no tool — ours included — can show you a real before-and-after score.
  • EU AI Act Article 50 places the watermarking obligation on AI providers, not on you as an individual using content you generated and own.

What Anthropic actually added to Claude output

On 2 August 2026, Anthropic started embedding a machine-readable watermark in text generated by Claude. It applies to every Claude model launched on or after that date, and it applies worldwide rather than only inside the EU.

The driver is Article 50 of the EU AI Act, which requires providers of generative AI systems to mark synthetic output in a machine-readable way. Anthropic chose to apply it globally rather than maintain two versions of the same model.

What matters for anyone trying to remove it is the shape of the thing. This is not metadata attached to a file, and it is not a set of invisible characters sprinkled through the text. It is a statistical pattern in the words themselves.

Anthropic's own description

"Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick." And, decisively: "Nothing is added to the text and there are no hidden characters."

That second sentence is the one to hold on to. It rules out an entire category of tool in a single line, and it comes from the company that built the watermark.

How the SynthID watermark works

Anthropic uses SynthID-Text, the approach Google DeepMind published in Nature in 2024. The underlying idea traces back to a 2022 proposal by Scott Aaronson.

When a language model writes, it is repeatedly choosing the next token from a ranked list of candidates. Usually that choice involves a random element. Watermarking replaces the arbitrary randomness with a value derived from a secret key plus the few words immediately preceding. Across a long enough passage, the choices drift in a direction that looks unremarkable to a reader but is measurable to anyone holding the key.

That design explains the watermark's strengths and its weaknesses, and both matter if you are trying to get rid of it.

PropertyWhyWhat it means for you
Survives copy and pasteThe signal is the word choice, not the encodingMoving text between apps changes nothing
Survives translationClaude chose every word in the sourceRound-tripping through another language is not a reliable escape
Weak on short passagesToo few token choices to accumulate a signalA paragraph carries far less evidence than a full essay
Sparser on factual passagesConstrained text has few valid alternatives to biasTechnical and factual writing is marked more lightly
No hidden charactersNothing is inserted into the text at allCharacter-stripping tools have nothing to find
What the mechanism implies for removal

The last two rows are also why detection is probabilistic rather than binary. A watermark detector returns a confidence score over a passage, not a yes-or-no verdict on a sentence.

Does Claude watermark code?

This is the question developers have asked loudest since the rollout, and it has a specific answer rather than a reassuring one.

Code carries less watermarking than prose, for the same reason factual writing does: the mark is encoded by choosing between equally valid alternatives, and code offers far fewer of them. A function that has to compile, pass its tests and use the names already defined around it leaves the model very little room to pick a different token without changing behaviour. There is nowhere to hide a signal.

That is not a carve-out. Anthropic has not said code is excluded from watermarking — it has said code has fewer opportunities to mark. The distinction matters, because the discretionary text inside a file is a different story.

Where a signal can still sit in a code file

Comments, docstrings, commit messages, README and documentation text, error strings, and variable or function names where several equally good options existed. These are the parts of a file where the model genuinely had a choice, and they are exactly the parts that read like prose.

So a tightly constrained implementation function is close to unmarkable, while a heavily commented module or a generated README sits much closer to ordinary prose. Detection also needs volume, and a short snippet gives a detector very little to work with.

The second mark: C2PA metadata on files

Anthropic uses two complementary techniques, and almost every article about removal only covers the first. Alongside the text watermark, it attaches signed provenance metadata to files, following the C2PA open standard.

These behave in opposite ways, which is why lumping them together produces such bad advice.

Text watermarkC2PA metadata
Where it livesIn the word choices themselvesAttached to the file, not the content
Survives copy and pasteYesNo — copying the text out leaves it behind
Can you strip it?No, only rewrite itYes — a re-save or format conversion drops it
Can you verify it is gone?Not today — no public detectorYes — metadata is readable with any C2PA tool
The two marks Anthropic applies If you pasted text out of a conversation, you never had the C2PA metadata in the first place. It only applies to files.

Anthropic also lists three conditions under which either mark may simply not be detectable: the text has been heavily edited, paraphrased, translated or mixed into other writing; the passage is very short, leaving too little signal; or it came through a platform or file type where that marking type was not supported.

Why zero-width character removers do nothing here

Search for a Claude watermark remover and most of what comes back is a text box that scans for invisible Unicode — zero-width spaces, zero-width joiners, byte-order marks, exotic space characters — and deletes them. Several of these sites appeared within days of Anthropic's announcement.

Those tools are not lying about what they do. They genuinely find and remove invisible characters. The problem is that Claude's watermark is not made of invisible characters, so removing invisible characters cannot remove it.

What a green checkmark actually means

When one of these tools reports "watermark removed" on Claude text, it is telling you it found no zero-width characters. That was true before you pasted the text in. The statistical pattern it did not look at is still there.

This is not a fringe complaint. BleepingComputer's assessment of the wave of new tools was blunt: AI watermark removers flooded the web, and almost none of them can prove they work. An independent researcher testing popular text cleaners found one let the most common hidden-payload technique through untouched.

There is a real use for these cleaners, and it is worth being fair about it: chat interfaces do sometimes leave invisible characters in text you copy out of them. That is a genuine artefact worth cleaning. It is simply a different problem from the one Anthropic introduced in August.

The distinction, laid out properly:

What actually removes a SynthID watermark

Anthropic, on what defeats it

"Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will."

The mechanism makes the reason obvious. The evidence is the sequence of choices Claude made. Replace a choice and you replace the evidence for it. Replace some of them and you weaken the signal without eliminating it, because a detector aggregates across the whole passage — a partially rewritten essay can still carry enough marked stretches to score above threshold.

Anthropic's support documentation similarly acknowledges that heavy editing, paraphrasing and translation degrade the mark. That is a meaningfully different claim from "paste it into a cleaner and it is gone".

Changes the signal

  1. A full paraphrase. Every sentence re-expressed with different word choices. This is the case Anthropic explicitly names.
  2. Sentence-level restructuring. Splitting, merging and reordering sentences changes both the tokens and the context each subsequent choice is keyed against.
  3. Substantive manual rewriting. Rewriting in your own voice, with your own examples. Slower than any tool, and the only version nobody can dispute.

Does not change the signal

  1. Stripping invisible characters. There are none to strip. Anthropic's documentation is explicit on this point.
  2. Find-and-replace on em dashes or stock phrases. Swapping punctuation and a handful of giveaway words leaves the overwhelming majority of token choices untouched.
  3. Changing formatting, fonts or file type. The watermark is in the words. Re-saving as a different file format carries it along unchanged.

How RewriteAI's rewrite engine handles this

RewriteAI is a full-rewrite paraphrase engine. It is not a character filter and it does not scan for hidden marks. It takes a passage and re-expresses it, replacing word choices across the text — which is the mechanism Anthropic names.

What we are not claiming

We do not claim guaranteed watermark removal. Anthropic's detection API is not public, so no tool — ours included — can currently show you a verified before-and-after SynthID score on Claude output. Anyone who tells you otherwise cannot back it up either. What we can tell you is what the engine does: it replaces the words.

0 / 300 words

Free plan: 500 words per month, 300 words per request, English only, account required.

If you are going to do this, do it properly

Longer inputs and a stronger paraphrase setting replace more of the token choices. Rewriting two sentences out of a 900-word essay leaves almost all of the original signal in place.

Can anyone verify a Claude watermark was removed?

Not on Claude output, and not today. Anthropic has said it will offer a watermark detection API and is working out the implementation details, but it has not shipped. Until it does, nobody outside Anthropic can measure whether a given passage still carries the mark.

That is an uncomfortable thing for a page like this to admit, and it is why the rest of the market does not admit it. Every confident claim you have read this month about defeating Anthropic's watermark — ours included — is currently unfalsifiable.

There is a partial way around it. Google's SynthID-Text reference implementation is open source, including both the Weighted Mean and Bayesian detectors described in the Nature paper. That lets us generate watermarked text under a key we control, rewrite it, and measure the detector's confidence before and after.

The benchmark we are running, stated in advance

Generate watermarked and unwatermarked passages using the open SynthID-Text implementation. Pass the watermarked set through our rewrite engine. Score all three sets with the Bayesian detector and publish the distributions and the detection rate at a stated false-positive rate. The limitation, stated up front: this measures the open reference implementation under our own key, not Anthropic's production configuration. It is a directional proxy, not proof about Claude.

We will publish the numbers in this section when they exist, including if they are unflattering.

When you should not remove it

There are cases where removing the mark is the wrong call, and pretending otherwise would make this page less useful.

Leave it, or disclose instead:

  • Academic work submitted under a disclosure policy. The question is not whether the watermark is detectable — it is what you agreed to when you enrolled. Disclose the assistance.
  • Synthetic media depicting real people or events. Provenance signals exist for a reason here, and stripping them is the case the transparency rules were written for.
  • Anything where a reader's decision depends on believing a human wrote it unaided — expert testimony, medical or legal guidance, first-person reporting.

Reasonable cases for a rewrite:

  • Commercial copy you own, where a model produced a first draft and the finished text is your product.
  • Drafts you have already rewritten substantively, where a residual mark misrepresents how the text was actually made.
  • Internal documents where an automated provenance flag would create a misleading record of authorship.

Sources

Frequently Asked Questions

Does Claude watermark its output?

Yes. Since 2 August 2026, Anthropic embeds a machine-readable watermark in text from Claude models launched on or after that date. It applies worldwide, not only in the EU, and it is invisible to readers.

When did Anthropic start watermarking Claude?

2 August 2026, the date EU AI Act transparency duties took effect. It covers Claude models launched on or after that date. Anthropic has said it is working to add watermarking to models released before then.

Does Claude add hidden characters to text?

No. Anthropic's documentation states directly that nothing is added to the text and there are no hidden characters. The watermark is a statistical pattern in which words the model chose, not inserted content.

How do you remove a Claude watermark?

By rewriting the text so the word choices change. Anthropic says light editing probably will not remove it completely, but a complete rewrite where every word is replaced will. Character-cleaning tools do not affect it.

Does editing remove the Claude watermark?

Partially, at best. Detection aggregates across a whole passage, so editing a few sentences of a long document leaves most of the signal intact. The more of the original wording survives, the more evidence remains.

Can anyone detect a Claude watermark right now?

Only Anthropic. It has announced a watermark detection API but has not released it, so no third party can currently check whether text carries the mark — or confirm that a removal tool worked.

Does Claude watermark code?

Code carries less watermarking than prose, because working code offers few equally valid alternative tokens to choose between. Comments, docstrings, READMEs and error strings are discretionary text and can still be marked.

Can I just ask Claude to remove its own watermark?

No. Asking Claude to rewrite the text produces new Claude output, which is watermarked again. Any model that watermarks its output will mark whatever it regenerates for you.

Does Claude add anything to files as well as text?

Yes. Anthropic attaches signed C2PA provenance metadata to files, separately from the text watermark. Unlike the watermark, that metadata is strippable — it does not survive a re-save, a format conversion, or copying the text out.

Does the Claude watermark survive translation?

It can. Anthropic notes that watermarking applies to translations because Claude chose every word in the source. Translating through another model is not a reliable way to strip the mark.

Is removing a Claude watermark illegal?

EU AI Act Article 50 places the watermarking duty on AI providers, not on individuals using content they generated and own. Publishing realistic synthetic media carries a separate personal disclosure duty, and institutional rules apply independently of the law.

Rewrite Claude output properly

A full paraphrase replaces the word choices the watermark is built from. No character tricks, and no claims we cannot back up.

Try the rewriter

Free plan: 500 words per month, 300 words per request. English only. Account required. We do not claim guaranteed watermark removal — no tool can currently verify it.